APHINIA - Your Weekly CISO Wire
Here’s your weekly update on comings and goings, jobs, networking opportunities and actionable insights:
These are the most recent appointments and promotions of your cybersecurity peers. Say “CONGRATS!”🥂 to:
Stephen Garcia was appointed as CISO at BreachRx.
Michael Rapino was appointed as CISO at Dollar Bank.
Joe Sagona was appointed as CISO at American Electric Power.
Chaim Mazal was appointed as CISO at GitLab.
Geoff Roten was appointed as CISO at ScionHealth.
Thomas Hill was appointed as CISO at Candescent.
Andrew Becherer was appointed as CISO at Socket.
Manju Mudé was appointed as CISO at the U.S. Department of the Treasury.
Jeff Hudesman was appointed as CISO at Lithic.
Appointed? Promoted? Let us know!
Aphinia is growing! Say hello, reach and connect with our new members:
Larry Xu, CISO, Prism Data Technologies
Abdul Khadir, OT Cyber Security Architect, Estee Lauder Companies
Geoff Hancock, CISO, Unacast
Mariska Calabrese, VP Security, beehiiv
Robert Novo, Head of Compliance and US Gov Network Engineering, Oracle
Welcome on board!
Who in your network can benefit from Aphinia? Please send them here »
Not yet a member? Apply here »
Do you want to share your story with fellow CISOs?
Do you want to impart your wisdom and share actionable insights? And, importantly, to further enhance your personal brand so that you would get:
a new Advisory role or a consulting gig
a promotion or appointment
a book deal or a speaking engagement at industry conference
Respond to this post and we will book time for a conversation.
Meanwhile, check out this session with Cass Mack (CISO, TensorWave) during our 2026 RSAC executive breakfast on actionable insights for CISOs.
Full interview here»
Several important events happened that merit your attention:
U.S. House rejects FISA extension: The U.S. house rejected a last-minute extension of FISA Section 702, putting the government’s foreign surveillance powers at risk of expiring. The vote was impacted by bipartisan concerns over President Trump’s appointment of Bill Pulte as acting director of national intelligence.
European regulators adopt unified data breach notification system: The European data protection board has adopted a common template to standardize how organizations report data breaches under GDPR Article 33.
Britain weakens telecom cyber defenses amid costs: Britain has scaled back proposed cybersecurity rules for telecom networks following industry concerns about cost and feasibility. Critics warn the changes could increase exposure to state-backed cyber threats like the Salt Typhoon campaign.
Poland introduces jail terms for streaming violent crimes online: Poland has passed a law imposing up to five years in prison for streaming violent crimes, including rape, murder, and animal cruelty.
Apple and UK police team up to combat iPhone theft: Apple has partnered with the Metropolitan Police to share device identifiers like IMEI numbers to prevent stolen iPhones from being reactivated or resold.
FBI builds fake town to train cyberattack investigators: The FBI has built a 22,000-square-foot replica town in Alabama to recreate real-world cyberattacks and train investigators in handling incidents like ransomware and digital breaches.
Senate rejects U.S. cyber force proposal: The U.S. Senate narrowly rejected an amendment to establish a dedicated Cyber Force as a new military branch, citing the need to wait for further feasibility studies. However, the defense policy bill still introduces a new senior cyber-focused Pentagon role aimed at improving coordination and reducing internal friction in cyber operations.
Industry news: Aryon security, an Israel-based cybersecurity startup company has raised $29 million. Coram AI, an AI-native physical security company has raised $35 million. Cyera, a New York–based cybersecurity company has raised $600 million. K2 Integrity acquired RiskFront AI. Cybri acquired WraithScan. Skyone acquired ADD IT.
These senior cybersecurity executive roles you may want to forward to your friends and colleagues:
Middle Georgia State University is looking for a Chief Information Security Officer in Macon, GA.
Bitsight is looking for a Chief Information Security Officer in Boston, MA.
Gulf Copper is looking for a Chief Information Security Officer in Galveston, TX.
Achieve is looking for a Chief Information Security Officer in Tempe, AZ.
FCCI Insurance Group is looking for a VP, Chief Information Security Officer in Sarasota, FL.
Alluvionic Inc is looking for a Virtual Chief Information Security Officer in Oberlin, OH.
Triplemoon is looking for a Virtual Chief Information Security Officer (Remote).
Bitget is looking for a Chief Information Security Officer (Remote).
Finance of America is looking for a SVP, Chief Information Security Officer (Remote).
JFrog is looking for a Field Chief Information Security Officer (Remote).
Looking for a job? Hiring? Let us know.
Our CISO Mastermind dinner in Alexandria around AWS Summit was awesome. Solid group of practitioners, candid off the record discussion on topics that mater, a lot of thought- and action-provoking insights. Couldn’t ask for more.
Quick Sign Up - Aphinia In-Person CISO Mastermind Dinners:
Events are filling up very fast. So if you are traveling to the conferences or local to these cities sign up today:
Black Hat - August 4, 2026 - Las Vegas, NV - Save your seat
Fal.Con - August 31, 2026 - Las Vegas, NV - Save your seat
Phoenix Mastermind - Sep 21, 2026 - Phoenix, AZ - Save your seat
Los Angeles Mastermind - Sep 22, 2026 - Los Angeles, CA - Save your seat
San Diego Mastermind - Sep 23, 2026 - San Diego, CA - Save your seat
Bay Area Mastermind - Sep 24, 2026 - Palo Alto, CA - Save your seat
SecTor - October, 5, 2026 - Toronto, ON - Save your seat
Re:Invent - Las Vegas, NV - Save your seat
Gartner IAM - Dallas, TX - Save your seat
=> Want to host or sponsor a CISO Mastermind around a conference you are going to or in the city where you live? Reach out!
Industry Events:
Black Hat is taking place on Aug 1-6, 2026 in Las Vegas, NV.
Mindfluence is hosting three events: Napa Valley - May 3-5, 2026, Lake Geneva - Sep 20-22, 2026, and Vail, CO - Nov 8-9, 2026.
Empower Summit is taking place on Sep 23-24, 2026 in Portland, OR.
Promo code for Aphinia members: YUahwGBe
Attending or hosting an event? Let us know!
Bad actors have been busy recently 📈:
A Salesforce data breach linked to the ShinyHunters gang exposed personal information from over 137,000 Infinite Campus school staff accounts, including names and contact details.
iRhythm Holdings disclosed a data breach after hackers used social engineering to steal patient personal and health information from third-party applications and demanded a ransom.
Chinese state-linked hackers breached REDCap servers and deployed InfiniteRed malware to steal sensitive medical research data from a North American institution.
The “Otlozhka” scheduling bot on the MAX platform was hacked, exposing over 30,000 channels after attackers exploited an unpatched vulnerability.
The University of Nottingham confirmed a cyberattack in which hackers accessed its student records system, exposing data from over 450,000 current and former students.
Personal information of over 37 million Coupang customers was exposed in a data breach that led South Korea to impose a record 624.6 billion won (roughly $409 million) fine on the company.
A security breach exposed the passport details of Argentina’s entire squad, including Lionel Messi, ahead of its World Cup warm-up match against Iceland.
Congressman Don Bacon had his Signal account hacked in a Russia-linked phishing attack, prompting an FBI investigation into the breach.
A suspected health data breach may have exposed the personal information of 67.1 million people in Thailand, prompting a parliamentary investigation.
Novo Nordisk disclosed a data breach exposing clinical trial data and healthcare professional details after attackers accessed its internal systems, though it says the data is not directly identifiable.
But a handful of guys were nabbed 👮♀️:
Conti ransomware operator arrested in US case: A Ukrainian national, Oleksii Oleksiyovych Lytvynenko, was arrested and pleaded guilty in the US for developing malware tools for the Conti ransomware group. He admitted involvement in the scheme and now faces up to 20 years in prison.
Ex-School district IT worker arrested for retaliatory cyberattacks: A former Iowa school district IT employee was arrested and later sentenced to 21 months in prison for carrying out a prolonged cyberattack against his former employer. The attacks disrupted school operations, deleted accounts, and caused nearly $60,000 in damages and recovery costs.
Vietnam police disrupt major online scam operation: Vietnamese police arrested four suspects and dismantled a group planning to establish a large-scale online scam center linked to fraud networks in Cambodia. Authorities seized computers and mobile devices, preventing the operation from becoming active.
Suspects arrested in Europol crackdown on crypto laundering network: Europol-led investigators dismantled the “AudiA6” crypto laundering service used by ransomware gangs to move about $364 million in illicit funds. Several suspects were arrested in a coordinated international operation that also seized assets and shut down the network.
Misha Sobolev
Aphinia
***
P.S.: Are you a senior GTM executive at a cybersecurity company wanting to get your story in front of 2,000+ of cybersecurity executives? Sponsor a thought leadership section in the next issue of CISO Wire.










